HealthPulse turns the health data your phone and wearables already collect into daily scores, trends and plain-language explanations. This policy explains what the app reads, what leaves your device, and the choices you have. It applies to the Android and iOS apps.
With your permission, HealthPulse reads data from Health Connect (Android) or Apple Health (iOS): activity (steps, distance, floors, calories, exercise sessions), heart rate, resting heart rate, heart rate variability, VO2 max, sleep, respiratory rate, blood oxygen, weight and body composition, nutrition and hydration, blood glucose, and, if you use cycle tracking, menstruation records. You choose which types to allow and can change that at any time in Health Connect or Health settings.
The app writes meals and water you log back to Health Connect / Apple Health, if you allow it.
Scores, trends, baselines, your food log and saved foods, meal photos, uploaded blood reports and their extracted values, your settings, and chat history stay on your device. Meal photos are never uploaded except for analysis when you ask for it (see below). Removing the app deletes this data. Data you wrote to Health Connect / Apple Health stays there until you delete it in that app.
AI features. When you ask a question or request a briefing or review, the app sends a summary built on your device: computed scores, daily averages and comparisons against your own baseline, recent workouts, body measurements, recent food-log totals and your own recent questions. It does not send raw minute-by-minute samples, and it never sends menstrual cycle or gait data. Food-log totals are only included if you accepted the meal disclosure and left the setting on; you can turn it off in Settings → Privacy & data.
Meal analysis. If you type a meal description or take or choose a meal photo, that text or photo (resized, with location metadata removed) is sent for analysis.
Blood reports. If you upload a lab report, the document (a PDF or images of it) is sent so the values can be read. You see a separate consent screen before the first upload.
How these requests are handled. Requests go to HealthPulse's AI service (hosted on Google Cloud / Firebase), which passes them to third-party AI model providers through OpenRouter to generate the reply. We do not store the content of requests or replies. The model providers process the content to answer and are subject to their own terms. We configure the service to avoid providers that train on prompts, but we cannot control the practices of third parties.
Service records. To enforce usage limits and prevent abuse, the service stores: a device ID (a one-way hash of an Android system identifier, or a random ID where that isn't available; it's not your advertising ID and can't be reversed), daily and lifetime request counts, a daily count by hashed IP address, and, for subscribers, a link between your purchase and your device (with your device's model name, such as “Pixel 8”, and when it was last used, so you can manage which devices use your Pro purchase). These records contain no health data or message content.
Subscriptions. Purchases are handled by Google Play (Android) or the App Store (iOS). We receive a purchase token or signed transaction to confirm your plan, and we do not receive your payment details.
Basic usage statistics. On each launch the app records, against your random device ID: first-seen and last-seen times, app version, operating system version and platform. It contains no health data and no personal information, and it's used to count installs and active devices.
Reference data. The app downloads a public blood-marker reference database from Firebase. No personal data is sent in that request.
We share information only with the providers that run the features above (Google Cloud / Firebase, Google Play or the App Store, and AI model providers via OpenRouter), and only to provide those features. We do not sell personal information, and we do not use it for advertising or share it with data brokers.
Data is sent over encrypted connections (HTTPS). On Android, sensitive local values are kept in encrypted storage. No method of transmission or storage is perfectly secure.
HealthPulse is not directed at children under 13, and we do not knowingly collect their data.
You can deny or revoke health permissions; disable AI features by not accepting the disclosures or by turning off food-log sharing; turn off notifications; delete your data by clearing it in the app or uninstalling; and request deletion of service records by emailing delete@saaramlabs.com.
If we change this policy we will update the effective date above and, for material changes, tell you in the app.
Saaram Labs · contact@saaramlabs.com · Data deletion requests: delete@saaramlabs.com